CSIDB logo
Incident

Policía de Seguridad Aeroportuaria

Incident posture

Attack window
Nov 2025
Location
Argentina
Status
Unknown
CIA posture
Available to members
Updated
2026-08-13 02:22

Linked entities

Victim
Policía de Seguridad Aeroportuaria
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Undetermined
Disclosed
Jan 2025
Resolved
Pending

Summary

Hackers compromised the payroll system of Argentina's airport security police, accessing personal and financial data and making small fraudulent salary deductions labeled as false entries. The breach occurred through a vulnerability in the bank that processes the agency's payroll, leading the agency to block some services and launch an internal cybersecurity awareness campaign. The article also notes other recent cyber incidents affecting Argentine government and private entities, though details remain limited.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Monday, local media reported that Argentina’s airport security police (PSA) had been targeted by a cyberattack that compromised personal and financial data of officers and civilian personnel. The unknown threat actor accessed PSA’s payroll records via a vulnerability in Banco Nación’s systems, the bank that processes the agency’s payroll. The actor deducted small amounts ranging from 2,000 to 5,000 pesos ($100 to $245) from employees’ salaries. The deductions were labeled falsely as “DD mayor” and “DD seguros.” Neither PSA nor Banco Nación have publicly commented on the breach.

The compromise exposed personal and financial data of PSA staff. In response, PSA blocked some of its services and launched an internal cybersecurity awareness campaign. The article notes that it remains unclear whether the attack was financially or politically motivated. The exact amount of stolen funds has not been determined. Additionally, the article references other recent cyber incidents in Argentina, including a December breach of e-government platforms (Mi Argentina and SUBE apps) attributed to the pseudonym "h4xx0r1337". A July ransomware attack on Telecom Argentina encrypted up to 18,000 workstations using stolen admin credentials. In April, hackers claimed to have obtained access to a Central Bank of Argentina database containing customer names and ID numbers.

Sources

Sources available to members: 1 source.

CSIDB